The invention relates to the related technical field of zero-trust networks, in particular to a
network data security protection method and
system based on multi-protection right control, and the method comprises the steps: connecting a terminal and a protection center, setting a primary
authorization mechanism, starting hierarchical
authorization of a right group, evaluating the risk in real time, interrupting the access if the risk does not accord with the threshold, and carrying out the
threat sharing. The technical problems that the authority is allocated only according to a fixed role, the enterprise business scene change and the user actual demand change cannot be adapted, the access of the user to the isolated data area resource is lack of fine-grained control, the situation of excessive authority granting or insufficient authority granting is easy to occur, and the data leakage risk is increased are solved; according to the invention, dynamic hierarchical management of the authority is realized by constructing a primary
authorization authentication mechanism and a hierarchical authorization
authentication mechanism, the authority is minimized to a single service instance, and fine-grained partitioning is carried out on resources, so that
data access control is more accurate, illegal
data access and
attack diffusion are effectively blocked, and
data access efficiency is improved. And the safety of the isolated data area is ensured.